s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1932615 high

📛 Threat Title

AsyncRAT: Domain that is used for botnet Command&control (C&C) lg.sonqhong.com

Category: AsyncRAT Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: AsyncRAT. Confidence: 75. First seen: 2026-09-25 03:05:17 UTC. Reporter: abuse_ch. Tags: asyncrat.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain lg.sonqhong.com UrlVoid 4 / 36

IOC database

Type
domain
Value
lg.sonqhong.com
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain that is used for botnet Command&control (C&C) attributed to AsyncRAT

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference ThreatFox IOCs
  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: AsyncRAT. Confidence: 75. First seen: 2026-09-25 03:05:17 UTC. Reporter: abuse_ch. Tags: asyncrat.

Remediations (10)

  • web:censys.com

    The malware supports remote command execution, file transfer, keylogging, screen capture, and credential harvesting, typically communicating with command-and-control (C2) servers over a custom TCP protocol with traffic encrypted via SSL/TLS, often using self-signed certificates that may present CN=AsyncRAT Server.

  • web:censys.com

    Overview AsyncRAT is a family of open-source Windows remote access trojans (RATs): an original codebase that has been forked repeatedly into dozens of descendant malware families. Its most prolific descendant, DCRAT (also known as DarkCrystal RAT), spawned a second generation of forks of its own. Censys searches on 16 June 2026 confirmed live command-and-control (C2) infrastructure for more ...

  • web:cyberint.com

    Introduced in 2019, AsyncRAT is classified as a remote access trojan (RAT) that primarily functions as a tool for stealing credentials and loading various malware, including ransomware. This RAT boasts botnet capabilities and features a command and control (C2) interface, granting operators the ability to manipulate infected hosts from a remote location. Despite its official GitHub page ...

  • web:socprime.com

    Abstract or unrelated examples will lead to misdiagnosis. Attack Narrative & Commands: An adversary has gained initial access and is preparing to establish a persistent Command-and-Control (C2) channel using AsyncRAT . To evade network-based signature detection, the attacker utilizes the RijndaelManaged .NET class to encrypt the traffic.

  • web:www.checkpoint.com

    Introduction to AsyncRAT A shortening of "Asynchronous Remote Access Trojan," AsyncRAT is a popular malware family used by a range of threat actors to target Windows systems. Remote access trojans are a type of malware that enables attackers to remotely control infected computers.

  • web:www.extrahop.com

    AsyncRAT and AsyncRAT variants are open-source malware that are easily accessible to attackers. This malware infects systems through user interaction, such as clicking phishing links or malicious ads. After a device is compromised, an attacker can remotely control the device, move laterally, or deploy secondary payloads and exfiltrate sensitive business information from the victim.

  • web:www.huntress.com

    AsyncRAT is a remote access trojan that enables attackers to control victim systems, steal data, and monitor activity. It works by embedding itself into target machines, often via phishing emails, and communicating with a command-and-control server to execute malicious actions.

  • web:www.microsoft.com

    Trojan:Win64/ AsyncRat is a standout as a versatile remote access trojan that first appeared on GitHub in 2019, positioned as a legitimate open-source remote management utility. However, records confirm that following its launch, it has been co-opted for illicit operations by threat actors, including entry-level cybercriminals and organized syndicates tied to ransomware efforts. It is built on ...

  • web:www.pointwild.com

    Successive stages decrypt to a final AsyncRAT DLL (Veukuzmw.dll) with screen capture and information stealing functionality. The final payload is a recognizable AsyncRAT build with screen capture and command-and-control capability. Each stage is examined in sequence below, with the payload recovered statically at every step.

  • web:www.zerosday.com

    AsyncRAT Analysis: Deep Dive into a Versatile Remote Access Trojan This report provides a comprehensive technical analysis of AsyncRAT , a popular open-source Remote Access Trojan (RAT) frequently observed in various cyber-attack campaigns. We delve into its infection vectors, persistence mechanisms, Command and Control (C2) communication, and advanced anti-analysis techniques. This analysis is ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.